Lazarus Under The Hood
First seen: 2017-04 •
Last seen: 2026-05
#LiberianFI • 2018-06
The Liberian Financial Institution incident is tracked in UN sanctions and financial-incident timeline reporting as part of a broader set of cyber-enabled thefts against financial institutions and cryptocurrency exchanges. The linked UN evidence attributes the wider activity to DPRK cyber actors, many operating under Reconnaissance General Bureau direction, and frames the theft and laundering of proceeds as sanctions evasion and revenue generation, but the provided excerpts do not include institution-specific malware, infrastructure, or intrusion-chain details.
2
Related Reports
1
Affected Countries
96
Months Since
Lazarus Under The Hood